CVE-2026-29072
- EPSS 0.01%
- Veröffentlicht 19.03.2026 21:49:33
- Zuletzt bearbeitet 23.03.2026 20:11:17
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, users who do not belong to the allowed policy creation groups can create functional policy acceptance widgets in posts under the right condi...
CVE-2026-28282
- EPSS 0.01%
- Veröffentlicht 19.03.2026 21:45:13
- Zuletzt bearbeitet 23.03.2026 20:16:43
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a security flaw in the discourse-policy plugin which allowed a user with policy creation permission to gain membership access to any pri...
CVE-2026-27936
- EPSS 0.02%
- Veröffentlicht 19.03.2026 21:42:36
- Zuletzt bearbeitet 23.03.2026 20:17:51
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a restriction bypass allows restricted post action counts to be disclosed to non-privileged users through a carefully crafted request. Versi...
CVE-2026-27935
- EPSS 0.03%
- Veröffentlicht 19.03.2026 21:33:38
- Zuletzt bearbeitet 23.03.2026 20:18:31
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a vulnerability in an API endpoint that discloses private topic metadata of admin users to moderator users even if the moderators do not...
CVE-2026-27934
- EPSS 0.04%
- Veröffentlicht 19.03.2026 21:17:43
- Zuletzt bearbeitet 25.03.2026 21:04:13
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a lack of visibility checks with a user action API endpoint that results in disclosure of the title and post excerpt to unauthorized use...
CVE-2026-27740
- EPSS 0.03%
- Veröffentlicht 19.03.2026 21:17:09
- Zuletzt bearbeitet 25.03.2026 00:58:33
Discourse is an open-source discussion platform. Versions prior to 2026.3.0-latest.1, 2026.2.1, and 2026.1.2 have a cross-site scripting vulnerability that arises because the system trusts the raw output from an AI Large Language Model (LLM) and rend...
CVE-2026-27570
- EPSS 0.01%
- Veröffentlicht 19.03.2026 20:52:17
- Zuletzt bearbeitet 25.03.2026 00:59:29
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, the onebox method in the SharedAiConversation model renders the conversation title directly into HTML without proper sanitization. Versions ...
CVE-2026-27491
- EPSS 0.03%
- Veröffentlicht 19.03.2026 20:47:54
- Zuletzt bearbeitet 25.03.2026 01:00:41
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, a type coercion issue in a post actions API endpoint allowed non-staff users to issue warnings to other users. Warnings are a staff-only mod...
CVE-2026-27454
- EPSS 0.04%
- Veröffentlicht 19.03.2026 20:39:28
- Zuletzt bearbeitet 25.03.2026 01:01:56
Discourse is an open-source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1, and 2026.1.2, requesting /posts/:id.json?version=X bypassed authorization checks on post revisions. The display_post method called post.revert_to directly...
CVE-2026-27166
- EPSS 0.03%
- Veröffentlicht 19.03.2026 20:29:22
- Zuletzt bearbeitet 25.03.2026 01:06:00
Discourse is an open source discussion platform. Prior to versions 2026.3.0-latest.1, 2026.2.1 and 2026.1.2, insufficient cleanup in the default Codepen allowed iframes value allows an attacker to trick a user into changing the URL of the main page....